[Bug 985716] Re: incorrect integer conversions in OpenSSL can result in memory corruption.

Alberto Bertogli albertito at blitiri.com.ar
Thu Apr 19 21:59:45 UTC 2012


** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2012-2110

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to openssl in Ubuntu.
https://bugs.launchpad.net/bugs/985716

Title:
  incorrect integer conversions in OpenSSL can result in memory
  corruption.

Status in “openssl” package in Ubuntu:
  Confirmed

Bug description:
  This is a very serious security bug, I guess you're already working on a release with the fix but just in case:
  http://seclists.org/fulldisclosure/2012/Apr/210

  The issue was already disclosed, so I will make it public so people
  know is reported (I guess you're already receiving millons of private
  bug reports)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/985716/+subscriptions




More information about the foundations-bugs mailing list